me again. One thing that was never cleared-up, simplified phishing? Does that lock the account completely or just for the offending IP address?
Example:
login CNCjerry badpass from 46.148.40.70
login CNCjerry badpass from 46.148.40.70
login CNCjerry badpass from 46.148.40.70
account locked or only locked from 46.148.40.70?
then immediately after account is locked:
login CNCjerry goodpass from 192.168.1.1 can this address login?
I've been getting hit by Iran on my two mail servers, only one is Mercury. There seems to be 5 servers in this botnet. They hit me about every 5 seconds, maybe more frequently. The log file hits 100meg in two months, for instance. So when I see it happening, and I don't check that often, i deny the entire botsubnet in an ACL on a 10Gig switch that feeds the server. Since September I've had to add about 15 addresses to the ACL, not a big hassle. When I add them everything settles down. By the way graywall really made a difference.
I can probably do this with an ACL, but is there a way to only allow logins to the mail server (authorized users) from a specific IP address range? For instance, my local subnet and then addresses on my cell network (if that is practical). If not, I think I'll figure out a way on my router.
Thanks, nothing but compliments from me. I've had so few issues for the past 21yrs, I think, I've used it.
Jerry
me again. One thing that was never cleared-up, simplified phishing? Does that lock the account completely or just for the offending IP address?
Example:
login CNCjerry badpass from 46.148.40.70
login CNCjerry badpass from 46.148.40.70
login CNCjerry badpass from 46.148.40.70
account locked or only locked from 46.148.40.70?
then immediately after account is locked:
login CNCjerry goodpass from 192.168.1.1 can this address login?
I've been getting hit by Iran on my two mail servers, only one is Mercury. There seems to be 5 servers in this botnet. They hit me about every 5 seconds, maybe more frequently. The log file hits 100meg in two months, for instance. So when I see it happening, and I don't check that often, i deny the entire botsubnet in an ACL on a 10Gig switch that feeds the server. Since September I've had to add about 15 addresses to the ACL, not a big hassle. When I add them everything settles down. By the way graywall really made a difference.
I can probably do this with an ACL, but is there a way to only allow logins to the mail server (authorized users) from a specific IP address range? For instance, my local subnet and then addresses on my cell network (if that is practical). If not, I think I'll figure out a way on my router.
Thanks, nothing but compliments from me. I've had so few issues for the past 21yrs, I think, I've used it.
Jerry